U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog
Overview
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious vulnerability in MLflow, identified as CVE-2026-64849, to its Known Exploited Vulnerabilities catalog. This flaw is categorized as a server-side request forgery (SSRF) with a high CVSS score of 9.3, indicating its potential severity. MLflow, which is used for machine learning lifecycle management, could allow attackers to manipulate server requests, potentially leading to unauthorized access or data exposure. Organizations utilizing MLflow should prioritize addressing this vulnerability to safeguard their systems. Given the critical nature of the flaw, it is essential for users to assess their exposure and implement necessary security measures promptly.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: MLflow
- Action Required: Organizations should implement available patches for MLflow as soon as they are released and review their configurations to mitigate potential SSRF vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-64849 is a critical server-side request forgery (SSRF) vulnerability in MLflow, a […]
Impact
MLflow
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should implement available patches for MLflow as soon as they are released and review their configurations to mitigate potential SSRF vulnerabilities. Regularly updating to the latest version of MLflow is also recommended.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Critical.